CVE-2014-3803
published 2014-05-21CVE-2014-3803: The SpeechInput feature in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to enable microphone access and obtain…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.37%
69.2th percentile
The SpeechInput feature in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to enable microphone access and obtain speech-recognition text without indication via an INPUT element with a -x-webkit-speech attribute.
Affected
80 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 35.0.1916.113 | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cq3j-mhjm-j845: The SpeechInput feature in Blink, as used in Google Chrome before 35
ghsa_unreviewed·2022-05-17
CVE-2014-3803 [MEDIUM] CWE-200 GHSA-cq3j-mhjm-j845: The SpeechInput feature in Blink, as used in Google Chrome before 35
The SpeechInput feature in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to enable microphone access and obtain speech-recognition text without indication via an INPUT element with a -x-webkit-speech attribute.
OSV
oxide-qt vulnerabilities
osv·2014-07-23·CVSS 7.8
CVE-2014-1730 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
A type confusion bug was discovered in V8. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via renderer crash, or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2014-1730)
A type confusion bug was discovered in Blink. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via renderer crash, or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2014-1731)
Multiple security issues including memory safety bugs were discovered in
Chromium. If a user were tricked in to opening a specially crafted website,
an attacker could potentiall
OSV
CVE-2014-3803: The SpeechInput feature in Blink, as used in Google Chrome before 35
osv·2014-05-21·CVSS 4.3
CVE-2014-3803 [MEDIUM] CVE-2014-3803: The SpeechInput feature in Blink, as used in Google Chrome before 35
The SpeechInput feature in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to enable microphone access and obtain speech-recognition text without indication via an INPUT element with a -x-webkit-speech attribute.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2014-07-23·CVSS 7.8
CVE-2014-1730 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
A type confusion bug was discovered in V8. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via renderer crash, or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2014-1730)
A type confusion bug was discovered in Blink. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via renderer crash, or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2014-1731)
Multiple security issues including memory safety bugs were discovered in
Chromium. If a user were tricked in to openin
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://blog.guya.net/2014/04/07/to-listen-without-consent-abusing-the-html5-speech/http://googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.htmlhttp://secunia.com/advisories/60372http://www.securityfocus.com/bid/67582https://code.google.com/p/chromium/issues/detail?id=360448https://src.chromium.org/viewvc/blink?revision=171373&view=revisionhttp://blog.guya.net/2014/04/07/to-listen-without-consent-abusing-the-html5-speech/http://googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.htmlhttp://secunia.com/advisories/60372http://www.securityfocus.com/bid/67582https://code.google.com/p/chromium/issues/detail?id=360448https://src.chromium.org/viewvc/blink?revision=171373&view=revision
2014-05-21
Published